StackRadar

galaxy Helm chart

cloudve

Scored 14 Sept 2026

Chart for Galaxy, an open, web-based platform for accessible, reproducible, and transparent computational biomedical research.

Latest 6.8.6 3 days agoapp version 26.1.1 0Artifact Hub

galaxy 6.8.6 deploys 3 container images: quay.io/galaxyproject/galaxy-min, library/nginx and tusproject/tusd. Across the 2 measured, 442 findings0 critical, 5 high 1 on CISA KEV. The highest contribution is ALPINE-CVE-2024-6119 in openssl 3.1.2-r0, fixed in 3.1.7-r0.

Radar Score

4,6010547389

442 findings over 2 of 3 images measured

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
quay.io/galaxyproject/galaxy-min×626.1.100272692,967
library/nginx1.22.0not yet scanned
tusproject/tusdv1.13.005201201,634

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

442 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGO-2024-3333golang.org/x/net@v0.14.00.33.0
LowDEBIAN-CVE-2026-78408util-linux@2.41-5no fix listed
LowGHSA-w7vc-732c-9m39pyjwt@2.12.12.13.0
LowGO-2024-3105stdlib@go1.21.01.22.7
LowDEBIAN-CVE-2026-73073vim@2:9.1.1230-2no fix listed
LowDEBIAN-CVE-2025-53906vim@2:9.1.1230-2no fix listed
LowGO-2026-4981stdlib@go1.21.01.25.10
LowDEBIAN-CVE-2023-31439systemd@257.13-1~deb13u1no fix listed
LowGO-2025-3563stdlib@go1.21.01.23.8
LowGO-2026-4977stdlib@go1.21.01.25.10
LowGO-2024-2610stdlib@go1.21.01.21.8
LowDEBIAN-CVE-2023-31437systemd@257.13-1~deb13u1no fix listed
LowDEBIAN-CVE-2026-16599wget@1.25.0-2no fix listed
LowGO-2026-4986stdlib@go1.21.01.25.10
LowGO-2026-4918stdlib@go1.21.01.25.10
LowGO-2026-4918golang.org/x/net@v0.14.00.53.0
LowGO-2026-4337stdlib@go1.21.01.24.13
LowDEBIAN-CVE-2026-6390nano@8.4-1+deb13u1no fix listed
LowDEBIAN-CVE-2023-31438systemd@257.13-1~deb13u1no fix listed
LowDEBIAN-CVE-2026-28419vim@2:9.1.1230-2no fix listed
LowGO-2026-4601stdlib@go1.21.01.25.8
LowDEBIAN-CVE-2026-78410util-linux@2.41-5no fix listed
LowDEBIAN-CVE-2026-35177vim@2:9.1.1230-2no fix listed
LowDEBIAN-CVE-2026-89161pcre2@10.46-1~deb13u110.46-1~deb13u2
LowGO-2026-5026golang.org/x/net@v0.14.00.55.0
LowGO-2026-5026stdlib@go1.21.01.25.13
LowDEBIAN-CVE-2025-14104util-linux@2.41-52.41.3-1
LowGO-2025-3420stdlib@go1.21.01.22.11
LowGO-2026-4342stdlib@go1.21.01.24.12
LowGO-2024-2598stdlib@go1.21.01.21.8
LowGO-2025-3751stdlib@go1.21.01.23.10
LowDEBIAN-CVE-2026-78409util-linux@2.41-5no fix listed
LowALPINE-CVE-2024-13176openssl@3.1.2-r03.1.8-r0
LowGHSA-2v4p-qf9q-27wjgoogle.golang.org/grpc@v1.57.01.82.2
LowGHSA-537c-gmf6-5ccfcryptography@48.0.048.0.1
LowGHSA-m425-mq94-257ggoogle.golang.org/grpc@v1.57.01.57.1
LowDEBIAN-CVE-2026-45130vim@2:9.1.1230-2no fix listed
LowGO-2025-4116golang.org/x/crypto@v0.12.00.43.0
LowGO-2026-4870stdlib@go1.21.01.25.9
LowGO-2025-4009stdlib@go1.21.01.24.8
LowGO-2026-4947stdlib@go1.21.01.25.9
LowGO-2025-4006stdlib@go1.21.01.24.8
LowDEBIAN-CVE-2026-73074vim@2:9.1.1230-2no fix listed
LowGO-2026-5037stdlib@go1.21.01.25.11
LowGO-2026-4971stdlib@go1.21.01.25.10
LowDEBIAN-CVE-2026-28418vim@2:9.1.1230-2no fix listed
LowGO-2026-5972stdlib@go1.21.01.25.13
LowGO-2026-6088stdlib@go1.21.01.25.13
LowGO-2026-6089stdlib@go1.21.01.25.13
LowGO-2026-6090stdlib@go1.21.01.25.13

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
6.8.6latest3 days ago26.1.105473894,601
6.8.55 days ago26.1.105473894,601
6.8.416 days ago26.1.105473894,601

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/cloudve/galaxy.svg)](https://charts.stackradar.io/charts/cloudve/galaxy)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 12 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.